WPBakery's vulnerability profile centers on its widely adopted WordPress page-builder plugin, which extends the core WordPress ecosystem with visual website-design capabilities. The recurring weaknesses reflect the plugin's role processing user-supplied content and file paths: cross-site scripting and path-traversal flaws recur across its disclosures, typical of web-facing content-management extensions. Defenders should track this vendor's updates alongside their WordPress deployments and validate that user-privilege and input-filtering controls are appropriately configured; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpbakery over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5709HIGH The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it pos | Aug 6, 2024 | 8.8 | 27 | NO | NO |
CVE-2025-11160MEDIUM The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in all versions up to, and including, 8.6.1. This is due to ins | Oct 15, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-4968MEDIUM The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separat | Jul 24, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-10006MEDIUM The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, 8.6 due | Oct 18, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-11161MEDIUM The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This is | Oct 15, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-7502MEDIUM The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to in | Aug 6, 2025 | 5.4 | 19 | NO | NO |
CVE-2024-5708MEDIUM The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 due to insufficien | Aug 6, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1842MEDIUM The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient in | May 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1805MEDIUM The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input | May 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-43953MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder classic-addons-wpbakery- | Aug 29, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpbakery.
Media articles that mention a CVE ID that affects a product developed by Wpbakery — matched by CVE ID, not by vendor name.